Code Red is a fast-spreading Windows worm family first observed in July 2001 that targeted Microsoft IIS web servers by exploiting a buffer-overflow flaw in the indexing service. The original worm was memory-resident and propagated by scanning for vulnerable internet-facing servers, causing large-scale disruption through aggressive self-replication and scan traffic. Early variants defaced some hosted web content and included a scheduled denial-of-service routine aimed at a U.S. government website during part of each month. A later and more virulent variant improved propagation by using better randomization for target selection, enabling extremely rapid global spread across hundreds of thousands of unpatched systems in hours and causing collateral instability in network-connected devices with web interfaces due to the volume of probing traffic.
Code Red primarily affected Windows systems running vulnerable IIS server software. Its spread depended on exposed, unpatched services rather than user interaction, making rapid patching and service hardening the principal defenses. The worm became a defining example of early internet-scale malware outbreaks and is frequently cited alongside Nimda and SQL Slammer in discussions of vulnerability-driven mass compromise.
A related but distinct worm, commonly referred to as Code Red II, exploited the same IIS vulnerability but differed materially in behavior. Unlike the original Code Red, Code Red II installed a persistent backdoor for later remote access and used locality-biased scanning to find additional targets, making it more dangerous from a post-compromise perspective. The broader Code Red family is historically significant for demonstrating how quickly self-propagating malware could weaponize a disclosed server vulnerability and disrupt global networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
On June 18, 2001 eEye released information about a buffer-overflow vulnerability in Microsoft's IIS webservers. The remotely exploitable vulnerability ... allows system-level execution of code ... the ISAPI .ida filter fails to perform adequate bounds checking on its input buffers. On July 12, 2001, a worm began to exploit the aforementioned buffer-overflow vulnerability in Microsoft's IIS webservers.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm cited as part of the early-2000s outbreaks that caused reputational harm to Microsoft and drove its Trustworthy Computing security push.
Referenced as an early internet worm; later cited as an example of fast-spreading attacks with little or no warning.
Referenced as a historical worm outbreak used for comparison with the proposed Intelligent Worm model.
A well-known internet worm referenced as one of the major outbreaks that pushed the industry toward better security practices and visibility.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.